ssh-gui
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONOBFUSCATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The core functionality of the skill is to execute commands on a remote macOS host via SSH. It uses tools such as
cliclick,screencapture, andosascriptto perform mouse clicks, keystrokes, and screen captures. - [OBFUSCATION]: The
bin/ssh-guihelper script uses Base64 encoding to wrap AppleScript payloads before sending them to the remote host for execution. This is implemented as a transport reliability mechanism to ensure scripts are transmitted correctly over the SSH connection. - [DYNAMIC_EXECUTION]: The skill dynamically generates AppleScript strings based on the task (e.g., targeting specific application names or menu items) and executes them on the remote machine using
osascript. - [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to ingest screenshots and UI hierarchy data from the remote system. This creates a surface for indirect prompt injection if the remote GUI displays untrusted content, such as a malicious website or document containing instructions for the agent.
- [DATA_EXFILTRATION]: The skill allows the agent to capture and transfer images and UI state from the remote machine to its own environment. While this is the intended purpose for "driving" the GUI, it provides a functional pathway for sensitive data to leave the remote host.
Audit Metadata